Privacy Policy

Last updated: August 19, 2026

This Privacy Policy explains what information NatureClips AI ("the Service") collects, why it is collected, how it is stored, and how you can remove it. NatureClips AI is a web application that discovers Creative Commons nature footage, produces short educational nature clips, and — when you choose to connect an account — uploads those clips to TikTok on your behalf.

1. Account and authentication data

To use the Service you create an account with an email address and password. Passwords are never stored in plain text; authentication is handled by our managed backend provider, which stores a salted hash of your password and issues session tokens to your browser.

We store your user ID, email address, sign-up date, and the timestamps of your sessions. We do not sell this information or use it for advertising.

2. TikTok OAuth and connected accounts

Connecting a TikTok account is optional and always initiated by you. Authorization happens through TikTok's official OAuth flow on TikTok's own domain — the Service never sees or receives your TikTok password.

When you authorize the Service, TikTok returns a limited set of profile information (such as your TikTok open ID, username, display name, and avatar URL) along with the scopes you approved. We store that profile information so the app can show you which account is connected and attribute uploads correctly.

3. TikTok access and refresh tokens

The Service stores the OAuth access token and refresh token issued by TikTok. These tokens are held server-side in our database, are protected by row-level security rules that restrict each record to the account that created it, and are never exposed to the browser or to other users.

Tokens are used solely to (a) upload clips you have approved to your TikTok account and (b) read back post status and basic performance metrics for those posts. The refresh token is used only to renew an expired access token. Tokens are deleted when you disconnect the account or delete your data.

4. YouTube API usage

The Service uses the YouTube Data API to search for and retrieve metadata about publicly available videos published under a Creative Commons license. Retrieved metadata includes video IDs, titles, descriptions, channel names, publication dates, durations, thumbnail URLs, and license status.

The Service does not require you to sign in to Google or YouTube, and it does not access any private YouTube account data. Use of the YouTube API is subject to the YouTube Terms of Service and the Google Privacy Policy.

5. Video processing

Source footage identified as eligible is processed to produce short vertical clips with captions and on-screen attribution to the original creator and license. Processing is performed by our rendering service; intermediate media files are temporary and are discarded once a clip has been produced.

Finished clip files are stored in our managed object storage so they can be reviewed and uploaded to TikTok. We do not process any video you did not initiate through the Service.

6. Stored clip metadata

For each clip we store metadata needed to operate the pipeline and to demonstrate licensing compliance: source video ID and URL, detected license, channel attribution, timestamps of the selected segment, transcripts or caption text, generated titles, descriptions and hashtags, automated quality and safety scores, publishing status, and the resulting TikTok post identifier.

7. Analytics

The Service records operational analytics such as pipeline runs, job outcomes, error events, API quota usage, and — for clips you publish — the performance metrics returned by TikTok (for example views, likes, comments, and shares). These metrics are used to show you dashboards and to improve the content suggestions the Service makes for your own account. They are not shared with third parties or combined across users for resale.

8. Disconnecting your account

You may disconnect a connected TikTok account at any time from the Social Accounts page in the app. Disconnecting revokes the stored access and refresh tokens with TikTok where supported and deletes them from our database. Once disconnected, the Service can no longer upload to or read data from that TikTok account.

You can also revoke access directly from your TikTok account settings, which immediately invalidates the tokens held by the Service.

9. Data deletion requests

You may request deletion of your account and all associated data at any time by contacting us at [contact email address]. Upon verification we will delete your account record, connected-account tokens, clips, clip metadata, and analytics history. Deletion requests are actioned within 30 days.

Deleting data in the Service does not delete content that has already been posted to your TikTok account; you control that content directly in TikTok.

10. Security

All traffic to and from the Service is encrypted in transit using HTTPS. Data at rest is stored with our managed backend provider using encrypted storage. Access to records is enforced with per-user row-level security rules, and privileged credentials such as API keys and OAuth secrets are stored as server-side secrets that are never sent to the browser.

No system can be guaranteed to be perfectly secure. If we become aware of a breach affecting your data, we will notify affected users without undue delay.

11. Third-party services

The Service relies on the following third parties:

  • TikTok — OAuth authorization, content posting, and post metrics.
  • YouTube Data API (Google) — discovery and metadata for Creative Commons footage.
  • Our managed backend and hosting providers — authentication, database, file storage, and application hosting.
  • AI model providers — used to score content, generate captions, titles, and hashtag suggestions from video metadata and transcripts.

Each third party processes data under its own privacy policy. We share only the data necessary for these functions.

12. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them.

13. Changes to this policy

We may update this Privacy Policy as the Service evolves. Material changes will be reflected in the "Last updated" date at the top of this page.

14. Contact

Questions, privacy requests, or data deletion requests can be sent to [contact email address].